SecOps Flashcards

1
Q

Differential versus incremental backup

A

Differential: backup everything since last FULL backup
Does not clear the archive bit

Incremental : backup everything since last backup
Clears the archive bits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Copy backup ?

A

Full backup without archive bit, used before system upgrades or patching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Miroring

A

Copying data exactly to other disk. Raid 1 for example

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Stripping

A

Using multiple disk to write
If parity, we could retrieve data if we are loosing a disk, with no parity we loosing data but write faster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Raid 0

A

Stripping without parity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Raid 1

A

Mirror, 2 disks with identical data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Raid 5

A

Stripping with distributed parity, need at least 3 disks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Database shadowing

A

Exact real copy on other location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Electronic Vaulting

A

E-vaulting
Using a remote backup service, backup are sent off-site electronically at certain interval

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Remote journaling

A

Sends transaction log file to a remote location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Lifecycle of DRP

A

Mitigation
Preparation
Response
Recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Rescue team

A

Activation/notification
Ecacuate employe
Notify
Pull the cable from infected servers
Shut down system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Recovery team

A

Failover
Responsible for getting the alternate site running
System rebuilmost critical systems first

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Salvage team

A

Failback
Responsible for returning to primary site
Least critical applications first to be sure it’s stable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Redundant site

A

Complete identical site to our production
Having staff at it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Hot site

A

Similar to redundant sote but only critical applications and sys
Lower specs sys often
Manual switch, < 1h

17
Q

Warm site

A

Similar to the hot sote but not real time data
Often restore from backup
Switch manually around 4-24h

18
Q

Cold site

A

Only having UPS, hvac, isp, generator but no system (need to be acquired)
The cheaper ans longer options can be > weejs

19
Q

COOP

A

How we keep operating in a disaster
Staff to alternate sites
What are all the operationnal things we need ?

20
Q

Cyber Incident Response Plan

A

Could be part of the DRP or not
Ddos, worms, ransomware, etc

21
Q

OEP Occupant Emergency Plan

A

How do we protect our staff, facilities in a disaster event

Focus on safety and evacuation, details how to evacuate, how often do our drills and the training

22
Q

2 Network forensic form ?

A

Catch it as you can: all packet passing through a certain traffic captured and then analysis in batch mode

Stop, look and listen: each packet is analyzed and only certain informations is saved for future

23
Q

MOU/MOA

A

Memorandum of Understanding/ Agreement

Staff are responsible for certains activities, legal documents